The cloud that enterprises and governments run on.
From what the cloud is to launching virtual machines, web apps and databases on Azure. Aligned to the AZ-900 Fundamentals and AZ-104 Administrator paths β the certifications employers ask for by name.
Read, do, complete, move on.
Open a lesson, read the notes, then mark it complete. Your progress is saved on this device.
AZ-900 Fundamentals: the concepts and the core services
This level gives you the language of the cloud and a map of Azureβs main services, security and pricing β exactly what the AZ-900 Fundamentals certification tests. No code required.
Cloud concepts
FoundationsβΊWhat the cloud is, and the three service modelsβ
The cloud is renting computing β servers, storage, software β over the internet instead of owning it. Microsoft runs data centres worldwide; you use what you need and pay for that.
Three models describe how much Microsoft manages versus you:
- IaaS (Infrastructure) β you rent raw virtual machines and manage the rest. Most control.
- PaaS (Platform) β you give Microsoft your app; it runs the servers for you.
- SaaS (Software) β you just use finished software, like Microsoft 365. Least worry.
βΊCapEx vs OpEx, and why it mattersβ
Buying your own servers is capital expenditure (CapEx) β a big payment upfront for hardware you then own and maintain. The cloud turns this into operational expenditure (OpEx) β a running cost you pay as you go, like electricity.
This is the business heart of the AZ-900 exam, and it is not just accounting. OpEx means you can start tiny, with no capital, and only pay more as you grow and earn.
βΊRegions, availability and the shared responsibility modelβ
Azure is organised into regions (geographic areas of data centres). Within many regions there are Availability Zones β physically separate data centres β so you can run across zones and survive one failing.
The shared responsibility model is the rule you must never forget: Microsoft secures the cloud itself (buildings, hardware, network); you are responsible for your data, your accounts, and your access settings. The split shifts with the service model β more is yours with IaaS, less with SaaS β but your data and identities are always yours to protect.
North Europe (Ireland) and West Europe (Netherlands) regions usually give good latency. Azure also has a South Africa region (Johannesburg) β test both and measure for your users.Core Azure services
The toolboxβΊCompute: VMs, App Service and Functionsβ
Azure gives you several ways to run code, from most control to least management:
- Virtual Machines β full computers you control (IaaS).
- App Service β host a website or API; Azure manages the servers (PaaS).
- Azure Functions β run a small piece of code on an event, no server at all (serverless).
- Azure Kubernetes Service (AKS) β managed Kubernetes for containers.
The skill is choosing the simplest option that fits. A standard website belongs on App Service, not on a VM you have to patch yourself.
βΊStorage and networking basicsβ
Azure Storage holds your data. The workhorse is Blob Storage for files β images, videos, backups β with hot, cool and archive tiers that trade cost against access frequency, just like other clouds.
Networking starts with the Virtual Network (VNet) β your private network in Azure. Resources inside it talk to each other privately, and you open access to the outside world deliberately with Network Security Groups (NSGs), which act as firewalls.
βΊIdentity with Microsoft Entra IDβ
Microsoft Entra ID (formerly Azure Active Directory) is Azureβs identity service β it manages who your users are and what they can sign in to. It is the front door to everything.
Two ideas carry it: authentication (proving who you are) and authorisation (what you are allowed to do). The single most important security feature it offers is Multi-Factor Authentication (MFA) β requiring a second proof, like a code on your phone, beyond the password.
Security, identity and governance
TrustβΊDefence in depth and Azure security toolsβ
Good security is not one wall but many layers β defence in depth β so that if one fails, others still protect you. Azure provides tools at each layer: NSGs and Firewall at the network, Entra ID at identity, encryption for data, and Microsoft Defender for Cloud watching the whole thing and scoring your security posture.
For the exam and for real life, know that data is encrypted at rest (while stored) and in transit (while moving) by default on Azure β a strong baseline you get for free.
βΊRole-Based Access Control (RBAC)β
RBAC is how you control who can do what in Azure, built on least privilege: grant each person only the access their job needs. You assign a role (a set of permissions) to a user or group, scoped to a specific resource, resource group or subscription.
βΊGovernance: subscriptions, groups and tagsβ
Azureβs structure keeps large estates tidy: a subscription is a billing and management boundary; resource groups bundle related resources so you can manage and delete them together; tags are labels (like env=prod or project=academy) that help you track cost and ownership.
Azure Policy lets you enforce rules automatically β for example "no one may create resources outside Europe" β so mistakes are prevented, not just caught later.
Pricing and managing cost
Spend wiselyβΊHow Azure pricing worksβ
Most Azure services are pay-as-you-go: you pay for what you consume β compute per second, storage per gigabyte, data transfer per gigabyte. Prices vary by region and by service tier.
Two tools help you plan: the Pricing Calculator (estimate a designβs cost before you build) and the Total Cost of Ownership (TCO) Calculator (compare cloud against running your own servers). Use the Pricing Calculator before every real project β guessing at cloud cost is how bills surprise people.
βΊSaving money: reservations and right-sizingβ
Pay-as-you-go is flexible but not always cheapest. If you know you will run a server for a year or more, a Reserved Instance commits you to it in exchange for a large discount. Right-sizing means picking a VM that matches real need, not the biggest one "to be safe".
βΊCost Management and budgetsβ
Microsoft Cost Management shows where your money actually goes β by service, by resource group, by tag β and lets you set budgets with alerts. Set a budget on day one and let Azure email you well before you reach your limit.
AZ-104 Administrator: deploy and manage real resources
Now you administer Azure for real β identity, compute, storage, networking and deployment β using the portal, the Azure CLI and Bicep. These are the day-to-day skills of an Azure Administrator (AZ-104).
Identity and the tools
Access and controlβΊManaging users, groups and the Azure CLIβ
An administrator lives in identity. In Entra ID you create users, bundle them into groups, and assign access to the group β so a new hire gets the right access just by joining the group, and loses it by leaving. This scales far better than per-person grants.
You will do much of this with the Azure CLI (az) β scriptable and repeatable β and Cloud Shell, a browser terminal with az ready to go.
az login then az group list --output table. Because it is commands, you can script onboarding β "create this user, add to these groups" β and run it identically every time.βΊRBAC assignments in practiceβ
Beyond understanding RBAC, the administrator assigns it correctly. The practical rules: assign roles to groups, not individuals; scope to the narrowest level that works (resource group over subscription); and audit assignments regularly to remove access people no longer need.
az role assignment create --assignee dev-team --role Reader --resource-group academy-rg. One command covers the team now and everyone who joins the group later.βΊConditional Access and MFA at scaleβ
Conditional Access (an Entra ID feature) lets you set smart sign-in rules: "require MFA when signing in from outside the office", or "block sign-ins from countries we never operate in". It applies security based on context, not a blanket rule that frustrates everyone.
Compute administration
Run the workloadsβΊDeploying and sizing virtual machinesβ
The administrator creates VMs with the right size, image and disk, in the right region, and knows how to resize them as needs change. You choose a VM series for the workload (general-purpose, compute-optimised, memory-optimised) and attach managed disks for storage.
az vm create --resource-group academy-rg --name web-1 --image Ubuntu2204 --size Standard_B1s. The B-series is burstable and cheap β ideal for dev and low-traffic workloads where you do not need constant full power.βΊScaling: availability sets and scale setsβ
One VM is a single point of failure. For reliability you spread across an Availability Set or Availability Zones so one hardware fault does not take you down. For handling variable load you use a Virtual Machine Scale Set β a group of identical VMs that grows and shrinks automatically with demand.
Pair a scale set with a load balancer and you have a system that absorbs a traffic spike and then shrinks back down to save money when it is quiet.
βΊApp Service and containersβ
Not everything should be a VM. App Service hosts web apps and APIs as a managed platform β you deploy code or a container and Azure handles the servers, patching, scaling and HTTPS certificate. For container-heavy systems, Azure Container Apps or AKS run your containers managed.
Storage and databases
Persist dataβΊStorage accounts, blobs and accessβ
Data lives in a storage account, which holds blobs (files), file shares, queues and tables. The administrator sets the access tier (hot/cool/archive), configures redundancy (how many copies, and whether across regions), and controls access with SAS tokens β time-limited keys that grant exactly the access needed and then expire.
βΊAzure SQL and Cosmos DBβ
Two managed databases cover most needs. Azure SQL Database is managed SQL Server β relational, familiar, with backups and high availability handled for you. Azure Cosmos DB is a globally-distributed NoSQL database for apps that need low latency for users anywhere and flexible data.
Choose relational (Azure SQL) for structured, related data (finance, inventory); choose Cosmos DB when you need global reach and flexible documents (a product catalogue serving several countries). Either way, "managed" means you run a serious database without being a full-time DBA.
βΊBackup and recoveryβ
An administrator who cannot restore data is not doing the job. Azure Backup protects VMs, databases and files on a schedule, and Azure Site Recovery can fail an entire system over to another region in a disaster.
Networking, monitoring and automation
Connect and operateβΊVNets, peering and DNSβ
The administrator designs the network: VNets divided into subnets, connected to each other with peering, protected by NSGs, and named with Azure DNS. A clean network design β separate subnets for web, app and database tiers β is both more secure and easier to reason about.
For connecting Azure to an office or another cloud, a VPN Gateway creates a secure tunnel over the internet.
βΊAzure Monitor and alertsβ
Azure Monitor gathers metrics and logs from everything you run; Log Analytics lets you query them; alerts notify you when something crosses a threshold. The administrator builds dashboards for the signals that matter and wires alerts to email or SMS β the same golden-signals discipline, native to Azure.
βΊInfrastructure as Code with Bicepβ
Clicking in the portal is fine to learn; real administration is Infrastructure as Code. Azureβs native IaC language is Bicep (a clean, readable layer over ARM templates) β you describe your resources in a file, version it in Git, and deploy it repeatably. Terraform works on Azure too, if you prefer one tool across clouds.
az deployment group create --template-file main.bicep. Your whole environment is now code you can review, repeat and rebuild β Azure administration done the professional way.Eight labs on real Microsoft Azure
Reading is free and open. The labs are where it becomes real, so they live behind a free account, which keeps your progress and gives you a certificate.
Create a free Kaevor account to launch any lab and earn your certificate. One account, all your courses.
Create free accountLab 1 β Portal tour + budget
Create a resource group, explore the portal, and set a budget alert.
Lab 2 β Secure your identity
Create users and groups in Entra ID and turn on MFA for an admin account.
Lab 3 β RBAC done right
Assign a scoped role to a group with the Azure CLI, following least privilege.
Lab 4 β Launch a VM safely
Create a Linux VM and lock its NSG down to your own IP for SSH.
Lab 5 β Blob storage + SAS
Upload files to Blob Storage and share one with a time-limited SAS token.
Lab 6 β Deploy to App Service
Publish a web app to App Service and get a managed HTTPS URL.
Lab 7 β Monitor and alert
Build an Azure Monitor dashboard and wire up one real CPU alert.
Lab 8 β Deploy with Bicep
Define a VNet, VM and storage account in Bicep and deploy it as code.
Two levels, one path
Beginner (AZ-900)
Cloud concepts, core Azure services, security, identity and pricing β the Fundamentals certification foundation.
Intermediate (AZ-104)
Administer identity, compute, storage, networking and deployment with the CLI and Bicep β the Administrator skill set.